feat(mcp): allowlist Grok's connector callback and document the Grok path (#2158)

* feat(mcp): allowlist Grok's connector callback and document the Grok path

Grok custom connectors self-register through /api/mcp-oauth/register with
redirect_uri https://grok.com/connectors-oauth-exchange-code/, which the
built-in allowlist rejected with invalid_redirect_uri before consent. Add
the callback as an exact-path BUILT_IN_PATTERNS entry (trailing slash
optional, no prefix) with provider 'grok', named "Grok (xAI)" on the
consent page. Tests: accept, foreign-host and other-path rejection,
provider mapping, and a register route test for the Grok DCR shape.

Surface Grok next to ChatGPT: a "Using Grok?" side door on the onboarding
Claude step (one side door open at a time, telemetry step grok), a Grok row
under "Other clients" in the API & MCP settings tab using ?client=grok, and
sv/en strings for both. Docs: mcp-server rule, ARCHITECTURE, README,
registry entry (install section), DECISIONS.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EGbspj3hiNqvqTWZqdwysa
Signed-off-by: Emil <emilmattsson14@gmail.com>

* fix(mcp): cite X Corp's published Grok callback, test the consent label

Review pass on #2158: the allowlist comment and DECISIONS entry claimed
xAI publishes no callback and the value came from a live observation; X
Corp lists https://grok.com/connectors-oauth-exchange-code/ as the "Grok
(web)" redirect URL at docs.x.com/x-ads-api/mcp, and grok.com serves the
path itself (slash form 308s to no-slash on the same origin). Reworded
both to cite that. Adds the consent-page test for "Grok (xAI)" next to
the ChatGPT one and a JSDoc on the onboarding side-door toggle.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EGbspj3hiNqvqTWZqdwysa
Signed-off-by: Emil <emilmattsson14@gmail.com>

---------

Signed-off-by: Emil <emilmattsson14@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-09-02 14:42:39 +02:00
committed by GitHub
co-authored by Claude Fable 5.1
parent 61a76b1669
commit 6a85efb00a
14 changed files with 131 additions and 32 deletions
+5 -2
View File
@@ -1358,6 +1358,8 @@
"step_claude_chatgpt_steps": "In ChatGPT (Plus, Pro or Business): Settings → Apps → Advanced settings → turn on Developer mode. Choose Add custom connector, name it {appName} and paste the server address. Then start a new chat and ask for a walkthrough of your books.",
"step_claude_chatgpt_copy": "Copy server address",
"step_claude_chatgpt_copied": "Copied",
"step_claude_grok_link": "Using Grok?",
"step_claude_grok_steps": "On grok.com: Connectors → New Connector → Custom. Name it {appName}, paste the server address and sign in when Grok asks. Then start a new chat with the connector switched on and ask for a walkthrough of your books.",
"step_claude_expectation": "Claude lists the tools straight away. The first real question opens a login prompt: approve it and ask again.",
"step_claude_guide_link": "Guide: connect Claude step by step"
},
@@ -2600,10 +2602,11 @@
"connect_mcp_title": "Connect MCP client",
"connect_to_claude": "Connect to Claude",
"connect_to_claude_help": "Opens claude.ai with the URL prefilled. You review and confirm there; no API key needed. Your instance must be reachable from the internet. Claude lists the tools straight away; the first real question opens a login prompt, approve it and ask again.",
"other_clients": "Other clients: Claude Code, Cursor, plugin",
"other_clients": "Other clients: Grok, Claude Code, Cursor, plugin",
"claude_ai_manual": "claude.ai (manual)",
"works_with_ai": "Works with Claude, ChatGPT, and other AI assistants.",
"works_with_ai": "Works with Claude, ChatGPT, Grok, and other AI assistants.",
"claude_ai_instructions": "Go to <path>Settings → Connectors → Add custom connector</path> and paste the MCP server URL. You sign in via your {connectorName} account: no API key needed.",
"grok_instructions": "On grok.com go to <path>Connectors → New Connector → Custom</path> and paste the MCP server URL. Grok registers itself and opens the sign-in: no API key needed.",
"cursor_instructions": "Add to <code>~/.cursor/mcp.json</code> (global) or <code>.cursor/mcp.json</code> (per project). Cursor does not read <code>claude mcp add</code>.",
"terminal_runs_browser_login": "Run in the terminal, sign in via the browser:",
"connect_with_api_key": "Connect with an API key",
+5 -2
View File
@@ -1358,6 +1358,8 @@
"step_claude_chatgpt_steps": "I ChatGPT (Plus, Pro eller Business): Inställningar → Appar → Avancerade inställningar → slå på Utvecklarläge. Välj Lägg till anpassad connector, namnge den {appName} och klistra in serveradressen. Starta sedan en ny chatt och be om en genomgång av bokföringen.",
"step_claude_chatgpt_copy": "Kopiera serveradress",
"step_claude_chatgpt_copied": "Kopierad",
"step_claude_grok_link": "Använder du Grok?",
"step_claude_grok_steps": "På grok.com: Connectors → New Connector → Custom. Namnge den {appName}, klistra in serveradressen och logga in när Grok frågar. Starta sedan en ny chatt med connectorn påslagen och be om en genomgång av bokföringen.",
"step_claude_expectation": "Claude listar verktygen direkt. Första riktiga frågan öppnar en inloggning: godkänn den och ställ frågan igen.",
"step_claude_guide_link": "Guide: anslut Claude steg för steg"
},
@@ -2600,10 +2602,11 @@
"connect_mcp_title": "Anslut MCP-klient",
"connect_to_claude": "Anslut till Claude",
"connect_to_claude_help": "Öppnar claude.ai med adressen ifylld. Du granskar och godkänner där; ingen API-nyckel behövs. Kräver att din instans går att nå från internet. Claude listar verktygen direkt; första riktiga frågan öppnar en inloggning, godkänn den och ställ frågan igen.",
"other_clients": "Andra klienter: Claude Code, Cursor, plugin",
"other_clients": "Andra klienter: Grok, Claude Code, Cursor, plugin",
"claude_ai_manual": "claude.ai (manuellt)",
"works_with_ai": "Fungerar med Claude, ChatGPT och andra AI-assistenter.",
"works_with_ai": "Fungerar med Claude, ChatGPT, Grok och andra AI-assistenter.",
"claude_ai_instructions": "Gå till <path>Settings → Connectors → Add custom connector</path> och klistra in MCP-serverns URL. Du loggas in via ditt {connectorName}-konto: ingen API-nyckel behövs.",
"grok_instructions": "På grok.com: gå till <path>Connectors → New Connector → Custom</path> och klistra in MCP-serverns URL. Grok registrerar sig själv och öppnar inloggningen: ingen API-nyckel behövs.",
"cursor_instructions": "Lägg till i <code>~/.cursor/mcp.json</code> (globalt) eller <code>.cursor/mcp.json</code> (per projekt). Cursor läser inte <code>claude mcp add</code>.",
"terminal_runs_browser_login": "Kör i terminalen, loggar in via webbläsaren:",
"connect_with_api_key": "Anslut med API-nyckel",